Junglewise Threat Intelligence

CVE-2026-50355: Microsoft Active Directory Federation Services stack buffer overflow

CVE-2026-50355 · Severity: high · CVSS 7.5 · Published 2026-07-14

Executive brief

A security vulnerability exists in Microsoft's Active Directory Federation Services (AD FS), a component used to provide single sign-on access to systems and applications. An unauthorized attacker can exploit this flaw over the network to crash the service, preventing legitimate users from logging into their corporate accounts and applications. This results in a significant disruption to business operations and identity management services.

Technical details

A stack-based buffer overflow (CWE-121) exists in Microsoft Active Directory Federation Services (AD FS). The vulnerability is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N). By sending specially crafted requests to the AD FS endpoint, an attacker can trigger the overflow to crash the service, leading to a denial-of-service (DoS) condition. While the primary impact is availability, stack overflows can sometimes lead to remote code execution, though Microsoft has classified this specific instance as a DoS. Security updates were released in July 2026 to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 Version 1607 / 1809 Multiple versions prior to July 2026 updates
  • Microsoft Windows Server 2012 / 2012 R2 / 2016 / 2019 Multiple versions prior to July 2026 updates
  • Microsoft Active Directory Federation Services (AD FS)

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats